AWS 409: Lambda code signing and trusted deployment artifacts
Why this lesson matters
Lambda code signing restricts new zip-package deployments to artifacts signed by approved AWS Signer profiles. It verifies integrity and publisher policy at deployment, but it does not scan code, authorize runtime behavior, make old unsigned code disappear or protect every configuration change.
Components and trust boundaries
AWS Signer has signing profiles/profile versions and signing jobs. A signed zip package is stored in an authorized S3 location or supplied through the deployment flow. A Lambda code signing configuration lists allowed signing profile version ARNs and defines the untrusted-artifact action. The function is associated with that configuration, and all newly deployed function code and attached layers must satisfy it.
| Control | Protects | Important limit |
|---|---|---|
| Artifact digest/signature | Bytes and approved signer | Does not prove code safety |
| Signing profile version | Publisher trust policy | Profile administration is high privilege |
| Code signing configuration | Allowed publishers/action | Association can be removed if IAM permits |
| Warn mode | Visibility before enforcement | Still permits untrusted deployment |
| Enforce mode | Blocks validation failure | Existing code continues running |
| Lambda version/alias | Immutable code/config snapshot and traffic | Publishing needs its own authorization |
Separate builder, signer, deployment, code-signing-policy administrator and runtime roles. The build role produces a digest and evidence but cannot use the production signing profile. The signing role accepts only policy-compliant artifacts. The deploy role can use only the approved code signing configuration and signed object version, while security administrators control allowed publishers and enforcement.
IAM can require a particular configuration when functions are created or updated using the lambda:CodeSigningConfigArn condition key where supported. Also deny unauthorized deletion/update of the configuration and removal from protected functions. Audit Signer profile changes, signing jobs, association changes and function/layer updates.
Deployment validation behavior
Lambda validates package integrity, signature expiry, allowed-profile match and revocation when code is deployed. In Warn mode deployment proceeds, SignatureValidationErrors is emitted and CloudTrail records the warning. In Enforce mode the warning evidence is produced and deployment is blocked. Production policy should normally enforce; a Warn rollout is a measured migration step with an end date, not permanent protection.
Code-signing checks occur at deployment, not each invocation. Adding a configuration to a function does not remove already running unsigned code. Profile/signature revocation does not automatically stop versions already deployed. Inventory every version and layer, then replace or disable affected versions through an incident decision. Signing also does not validate container-image Lambda packages; use the ECR supply-chain controls from AWS408 for that packaging model.
Promote the exact signed bytes. Record source commit, build workflow, unsigned digest, signing-job ID, signed-object S3 Version ID, signed digest, profile version ARN, code signing configuration ARN, function version and alias traffic. Do not rezip after signing because metadata/order changes bytes and invalidates integrity.
Safe rollout and recovery
Before enforcement, inventory functions/layers and test a trusted package, unsigned package, tampered package, disallowed profile, expired signature and revoked signature. Alert on SignatureValidationErrors and CloudTrail changes. Change association and enforcement through reviewed infrastructure code; protect emergency changes with separate approval and short-lived sessions.
Deploy a signed package to a function version, run security/functional tests, then shift an alias progressively. Signing success is only an admission result; runtime tests and rollback still apply. Retain the prior signed function and layer artifacts, profiles/evidence and compatible configuration through the rollback window. If signer or S3 is unavailable, use a pre-signed, pre-verified rollback artifact rather than disabling enforcement blindly.
~~~bash aws signer list-signing-profiles aws signer list-signing-jobs --status Succeeded aws lambda get-code-signing-config --code-signing-config-arn CSC_ARN aws lambda get-function-code-signing-config --function-name FUNCTION aws lambda list-versions-by-function --function-name FUNCTION aws cloudwatch get-metric-statistics --namespace AWS/Lambda \\ --metric-name SignatureValidationErrors --start-time START --end-time END \\ --period 300 --statistics Sum ~~~
Workshop and failure analysis
Given four functions, six layers and ten artifacts, build a trust inventory, trace each production alias to signed bytes, and classify validation results. Write IAM condition/deny pseudopolicies, a Warn-to-Enforce migration, rollback procedure and revocation response. Explain which controls belong in Signer, Lambda, S3/KMS, CI and runtime monitoring.
Test 22 failures: build can sign, deploy can edit publishers, profile wildcard, configuration removable, Warn mistaken for block, metric unmonitored, existing unsigned version ignored, unsigned layer attached, layer signed by wrong profile, artifact modified after signing, wrong S3 version, signature expired, signature revoked, signer profile cancelled, revocation expected to stop runtime, signing treated as vulnerability scan, image package assumed covered, alias points to unverified version, rollback artifact deleted, emergency disables enforcement, cross-account KMS denial, and CloudTrail identity not correlated.
Cost and acceptance
Lambda code signing and Signer currently have no additional service charge for this use, but S3/KMS, logging, build/test runtime and Lambda execution remain billable. Verify current pricing. This lesson creates nothing. Submit trust/data flow, role matrix, artifact ledger, policy designs, six negative tests, rollout/revocation/rollback runbooks and all diagnoses. Pass requires separated signing authority, Enforce policy, signed layers and exact artifact-to-alias proof.